Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » FedRAMP » Joint Authorization Board

Joint Authorization Board

A Joint Authorization Board or JAB provides FedRAMP (Federal Risk and Authorization Management Program) authorization to cloud service providers. 

The Board consists of the Chief Information Officers (CIOs) from the DHS (Department of Homeland Security, DoD (Department of Defense), and GSA (General Services Administration). 

The JAB reviews authorization packages based on the priority queue for cloud businesses. It is also responsible for assessing the requirements under the FedRAMP security authorization and updating it if necessary. 

Once a business has been selected to be sponsored by JAB, it will be required to create a Readiness Assessment Report (RAR) within a period of 60 days. An RAR contains specific information regarding the capability of the business toward meeting FedRAMP guidelines and requirements.

The JAB designates a “FedRAMP Ready,” stamp after which shows the CSP has been assessed by a Third Party Assessment Organization (3PAO)  and is acceptable as per FedRAMP requirements. After this, a CSP is listed in the FedRAMP marketplace.

After FedRAMP authorization, the JAB continues to monitor the cloud products and services of these business entities, ensuring the continuation of their level of compliance with standards on security and their ability to address issues that arise.

If the JAB grants provisional approval for any cloud service, agencies are empowered to provide their own security authorizations and ATOs. The board must also notify agencies promptly of any changes or removals of provisional approvals.

Additional reading

Lessons from the GDPR violations of all time.

Lessons learned from the biggest GDPR violations of all time

Gone are the days when companies could simply implement a firewall, add privacy policies to their websites, implement basic authentication controls, and call it a day. Today, GDPR reigns supreme, and no one, not even Meta or Google, is off its radar.  Over 247 fines have been issued in the last two years. And with…
Understanding NIST 800 137: A Comprehensive Guide to Information Security Continuous Monitoring (ISCM)

Understanding NIST 800 137: A comprehensive guide to Information Security Continuous Monitoring (ISCM)

The National Institute of Standards and Technology (NIST) has long been a pivotal force in shaping global standards and guiding cybersecurity professionals. NIST has developed essential frameworks and guidelines that enhance the capabilities of both industry and government in identifying and responding to cyber threats. One such critical publication is NIST SP 800 137 which…

Your Guide To Infosec Compliance In 2025

It’s 2023, and the world of information security (infosec) is a very different place than what it used to be. As a company owner, you have to become much more aware of the regulatory requirements. But achieving infosec compliance with these regulations isn’t easy; you need a plan that takes into account the latest trends…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.